PT-2024-24281 · Ibm · Ibm Mq

CVE-2024-31919

·

Published

2024-06-28

·

Updated

2024-08-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM MQ versions 9.0 LTS through 9.3 CD
Description The issue is caused by an error processing messages when an API Exit using MQBUFMH is used, leading to a denial of service attack in certain configurations.
Recommendations For IBM MQ versions 9.0 LTS through 9.3 CD, consider disabling the API Exit using MQBUFMH as a temporary workaround to minimize the risk of exploitation. Restrict access to the affected configurations to prevent denial of service attacks until a patch is available.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31919

Affected Products

Ibm Mq